1 / 19
WGU C795 EXAM QUESTIONS AND ANWSERS 2022
1.A company's main asset is a physical working prototype stored in the research and development department. The prototype is not currently con- nected to the company's network.Which privileged user activity should be monitored?a.Accessing camera logs b.Adding accounts to the administrator group c.Running scripts in PowerShell d.Disabling host firewall (answer) a 2.A company performs a data audit on its critical information every six months. Company policy states that the audit cannot be conducted by the same employee within a two-year time frame.Which principle is this company following?a.Job rotation b.Two person control c.Least privilege d.Need to know (answer) a 3.A user is granted access to restricted and classified information but is supplied only with the information for a current assignment.Which type of authorization mechanism is being applied in this scenario?a.Need to know b.Constrained interface c.Duty separation d Access control list (answer) a 1 / 3
2 / 19
4.Which two data recovery components will back up a file and change the archive bit to 0?Choose 2 answers.a.Full backup b.Differential backup c.Incremental backup d.Copy backup (answer) a, c 2 / 3
3 / 19
5.A company wants to monitor the inbound and outbound flow of packets and not the content.Which defense-in-depth strategy should be implemented?a.The organization should use egress filtering on the network.b.Traffic and trend analyses should be installed on the router.c.The administrator should configure network data loss prevention.d.RADIUS authentication should be used on the bastion host. (answer) b 6.A penetration tester identifies a SQL injection vulnerability in a busi- ness-critical web application. The security administrator discusses this find- ing with the application developer, and the developer insists that the issue would take two months to remediate.Which defense-in-depth practice should the security administrator use to prevent an attacker from exploiting this weakness before the developer can implement a fix?a.Perform daily vulnerability scans b.Implement a web-application firewall c.Submit an urgent change control ticket d.Deploy an anti malware agent to the web server (answer) b 7.A company is concerned about securing its corporate network, including its wireless network, to limit security risks.Which defense-in-depth practice represents an application of least privi- lege?a.Implement mutual multifactor authentication b.Configure Wi-Fi-Protected Access for encrypted communication c.Disable wireless access to users who do not need it d.Implement an intrusion detection system (answer) c
- / 3